PT-2026-4535 · Typemill · Typemill

Adrien Brunner

·

Publicado

2026-01-23

·

Atualizado

2026-02-02

·

CVE-2026-24127

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Typemill versions 2.19.1 and below
Description Typemill is a flat-file, Markdown-based CMS for informational documentation websites. A reflected Cross-Site Scripting (XSS) issue exists in the login error view template login.twig. The username value is echoed back without proper encoding when authentication fails, allowing an attacker to execute script in the login page context.
Recommendations Update to version 2.19.2 or later.

Exploit

Correção

Improper Encoding or Escaping of Output

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24127
GHSA-65X4-PJHJ-R8WR

Produtos afetados

Typemill